Known Vulnerabilities for Obot by Obot-platform
Listed below are 5 of the newest known vulnerabilities associated with "Obot" by "Obot-platform".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-101084 json | obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated us... | Not Provided | 2026-09-27 | 2026-09-27 |
| CVE-2026-101065 json | Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart comma... | Not Provided | 2026-09-27 | 2026-09-27 |
| CVE-2026-101064 json | Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privil... | Not Provided | 2026-09-27 | 2026-09-28 |
| CVE-2026-101063 json | Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authenticat... | Not Provided | 2026-09-27 | 2026-09-28 |
| CVE-2026-101062 json | Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic ... | Not Provided | 2026-09-27 | 2026-09-27 |